Successful cyber attacks due to poor controls

Successful cyber attacks due to poor controls

Successful cyber attacks at Jaguar Land Rover and Heathrow Airport have once again highlighted the importance of ensuring businesses have robust security protocols in place.

"It appears this attack was carried out by the same groups who claimed responsibility for the M&S attack, this type of attack won’t just continue, but it will escalate – organisations need to be ready," says Rebecca Richards, Strident's compliance expert.

This attack was successfully carried out using social engineering techniques and taking advantage of the lack of cyber awareness within the organisations.

"It highlights the importance of employee awareness of social engineering techniques, data loss prevention tools and supply chain security."

They only target big businesses, don't they?

Big businesses hit the headlines because severe disruptions to work can affect thousands of customers and employees, causing the business huge financial pain. In the case of Jaguar Land Rover, the knock on effect to suppliers has been equally disruptive.

The frequency for these kind of attacks is rising dramatically, and businesses of all sizes are being affected. Closer to our home, a haulage firm, The Knights of Old based in Kettering, recently experienced a cyber attack which left their business with the administrators, and is now closing after trading for 160 years!

Train your employees to a documented standard

"Training for employees is a must as they are often the weakest link in the security chain – but security vetting and auditing suppliers is just as important – attackers can get to you through your third parties. Vetting and auditing reduces that risk," explains Rebecca.

According to research carried out by Vodafone, the average cost of a cyber attack to a small business is £3398, this rises to £5001 for businesses which have up to 50 employees. For a medium sized business this figure again rises to an average of £10,830 per breach, which does not include any legal fees or fines should the report be a personal data breach.

At Strident, our training is targeted to prevent these types of attacks, we show how these attacks are carried out and why they can be successful, and how employees can identify and thwart social engineering attempts.

The benefits of cyber awareness training

The typical benefits a company will see after installing a regular training / awareness program:

  • Cost savings – less human error, reduced “insider threat” risk, less chance of legal fees and fines
  • Risk reduction – security awareness training can reduce security related risks by up to 70%.
  • Fewer security incidents – organisations who implemented an effective security training program have reported 80% fewer successful phishing attacks
  • Reduced phishing link click rates – studies show that ongoing security awareness training reduces phishing link licks from 32% to just 5% within 1 year
  • Behavioural change – employees who ate subject to regular security awareness training, adopt secure behaviours both at work and at home, keeping both the business and themselves, up to 70% safer.

Businesses cannot afford to skip on security. In addition to comprehensive security software, Strident can offer invaluable cyber awareness training to ensure your employees understand the risks and what to do. To find out more, then please get in touch here.

Get the latest news from Strident

6 Steps for Sorted IT

ISO & Data Protection